Data transmission method and device and medium
By using the APUF circuit in data transmission to generate random keys and carrying the next-use key between network cards, combined with the uniqueness of the network communication routing path, the problem of insufficient security in some scenarios of traditional encryption methods is solved, and higher data transmission security and reliability are achieved.
Patent Information
- Application Number
- CN202510724138.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-18
AI Technical Summary
Traditional data encryption methods cannot meet higher security requirements in some scenarios, especially in the process of data transmission.
APUF circuit is used to generate random keys, and a different key is used for each data transmission, and the next-use key is encrypted through packets between network cards. Combined with the uniqueness of IP packet routing paths in network communication, it makes it difficult for attackers to intercept continuous messages. At the same time, the key is not retained in the network card, and only the key excitation is retained to reproduce the key.
Improve the security and reliability of data transmission, increase the difficulty of cracking by the uniqueness of different keys and IP packet routing paths each time, preventing the keys from being acquired by attackers, and ensuring the security and integrity of data transmission.
Smart Images

Figure CN120342610A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and particularly to a data transmission method, apparatus and medium. Background Art
[0002] The Transmission Control Protocol (TCP) is one of the core protocols in the transport layer of the Internet protocol suite, mainly responsible for providing reliable, sequential, and connection-oriented data transmission services. In data transmission, data is often encrypted to ensure the security of data transmission.
[0003] Currently, the common data encryption method is that the data sender encrypts the transmitted data through various encryption algorithms, and the receiver decrypts the data after receiving the encrypted data to obtain the original data, ensuring that the data is in an encrypted state during the transmission process. Currently, the common encryption algorithms mainly include: one or a combination of several of symmetric encryption, asymmetric encryption, hash algorithms, and hybrid encryption, providing multi-level security guarantees. Commonly, the Advanced Encryption Standard (AES), RSA (an asymmetric encryption algorithm), the Elliptic Curve Cryptography (ECC), and the Secure Hash Algorithm (SHA) have become the basis of secure communication and are widely used in fields such as the Internet, finance, electronic payment, and blockchain that attach great importance to data security. However, with the development of the times, traditional data encryption methods can no longer meet the higher requirements for data security in some scenarios.
[0004] Therefore, those skilled in the art now urgently need a data transmission method to provide a data transmission solution that is different from using traditional encryption algorithms and has higher security. Summary of the Invention
[0005] The purpose of the present invention is to provide a data transmission method, apparatus and medium to solve the problem of insufficient protection of traditional data encryption methods for data transmission.
[0006] To solve the above technical problems, the present invention provides a data transmission method applied to at least two network cards including APUF circuits. The method includes:
[0007] Whenever the first network card needs to send a message to the second network card, a random excitation is generated and recorded as the key excitation;
[0008] Based on the key excitation, a corresponding random response is generated by the APUF circuit, and the random response is encapsulated as the first key in the message to be sent;
[0009] Encrypt the data of the message to be sent using the second key carried in the message sent by the second network card to the first network card most recently, and send the encrypted message to the second network card; wherein, the second key is: the corresponding random response generated by the APUF circuit based on random excitation by the second network card;
[0010] When receiving the message returned by the second network card, generate the corresponding response by the APUF circuit based on the key excitation to obtain the first key;
[0011] Decrypt the message returned by the second network card using the first key to obtain the decrypted data and the new second key.
[0012] In an alternative embodiment, the messages encrypted using the first key or the second key further include: the handshake messages sent between the first network card and the second network card when establishing and / or disconnecting the communication connection with each other.
[0013] In an alternative embodiment, the first network card and the second network card establish a communication connection through a communication transmission protocol;
[0014] Encapsulating the random response as the first key in the message to be sent includes:
[0015] The option field for encapsulating the first key in the message to be sent.
[0016] In an alternative embodiment, encrypting the data of the message to be sent using the second key carried in the message sent by the second network card to the first network card most recently includes:
[0017] Encrypt the data carried in the message to be sent and the first key using the second key.
[0018] In an alternative embodiment, for the message of the first handshake sent by the first network card and the second network card when establishing a communication connection, the method further includes:
[0019] Encrypt the data part of the message using the first key, and encapsulate the unencrypted first key in the option field of the message.
[0020] In an alternative embodiment, before encrypting the data part of the message using the first key and encapsulating the unencrypted first key in the option field of the message, it further includes:
[0021] Determine whether there is a third key retained in local storage; wherein, the third key is: the second key carried in the last handshake message when the second network card disconnects the communication connection with the first network card;
[0022] If it exists, encapsulate the first key in the option field of the message, and encrypt the option field and the data part of the message with the third key.
[0023] In an optional embodiment, it further includes:
[0024] When the retention duration of the third key exceeds a preset retention threshold, delete the third key from local storage.
[0025] To solve the above technical problems, the present invention also provides a data transmission device, which is applied to at least two network cards including APUF circuits, and includes:
[0026] A random key module, configured to generate a random excitation and record it as a key excitation whenever the first network card needs to send a message to the second network card;
[0027] A key encapsulation module, configured to generate a corresponding random response by the APUF circuit based on the key excitation, and encapsulate the random response as the first key in the message to be sent;
[0028] A data encryption module, configured to encrypt the message to be sent with the second key carried in the message sent by the second network card to the first network card most recently, and send the encrypted message to the second network card; wherein, the second key is: the corresponding random response generated by the APUF circuit based on the random excitation by the second network card;
[0029] A key reproduction module, configured to generate a corresponding random response by the APUF circuit based on the key excitation to obtain the first key when receiving the message returned by the second network card;
[0030] A data decryption module, configured to decrypt the message returned by the second network card with the first key to obtain the decrypted data and a new second key.
[0031] To solve the above technical problems, the present invention also provides a data transmission device, including:
[0032] A memory, configured to store a computer program;
[0033] A processor, configured to implement the steps of the data transmission method as described above when executing the computer program.
[0034] To solve the above technical problems, the present invention further provides a non-volatile storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data transmission method described above are implemented.
[0035] A data transmission method provided by the present invention obtains a random key through an Arbiter Physical Unclonable Function (APUF) technology of an arbiter during each data transmission. Based on the physical characteristics of the APUF circuit, even if the excitation is the same, the responses output by different APUF circuits are different, so as to ensure the unpredictability and uniqueness of the key obtained during each data transmission. Therefore, encrypting data based on this key has higher security compared to traditional encryption schemes based on pre-agreed keys, or keys generated and distributed by identity certificates or third parties.
[0036] Moreover, in this method, the keys used for encryption during each data transmission are different. The key generated by each network card itself based on the APUF circuit is carried in the packet sent by the network card, and is used for another network card to encrypt data with this key when sending a packet to this network card next time. That is, the network card encrypts the current packet based on the key carried in the previous packet sent by another network card; and the current packet carries the key randomly generated by itself, which is used for another network card to encrypt the packet with this key when sending a packet next time. Therefore, only by receiving and successfully parsing the previous received packet can the current received packet be decrypted. Due to the characteristic that the routing paths of each Internet Protocol (IP) packet are different in network communication, it is very difficult for an attacker to intercept the packets continuously transmitted between two network cards, greatly increasing the difficulty of cracking data transmission.
[0037] In addition, when data is transmitted based on this method, the key used for data encryption itself is not retained in the network card, so there will be no problem that the network card itself is cracked by an attacker and the key is obtained to crack the encrypted data. This method only retains the random excitation (i.e., key excitation) when generating the key through the APUF circuit to reproduce the key when decrypting data in the next packet. Due to the physical characteristics of the APUF circuit, even if the key excitation retained in the network card is stolen, the attacker cannot reproduce the corresponding key to crack the encrypted data, further improving the security of data transmission.
[0038] In summary, when implementing data transmission based on this method, the keys used for each data transmission are different. An attacker cannot crack the transmitted data unless they intercept multiple consecutive packets. Due to the characteristic that each IP packet has a different routing path in network communication, it is very difficult for an attacker to intercept consecutive packets. Moreover, the key used for data encryption itself is not stored in the network card, so an attacker cannot obtain the key by attacking the network card and then crack the transmitted data. Therefore, the data encryption transmission implemented based on this method has higher security and reliability.
[0039] The data transmission device and non-volatile storage medium provided by the present invention correspond to the above method and have the same effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the embodiments of the present invention, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0041] Figure 1 It is a structural diagram of a network card integrated with an APUF chip provided by an embodiment of the present invention;
[0042] Figure 2 It is a flowchart of a data transmission method provided by an embodiment of the present invention;
[0043] Figure 3 It is a structural diagram of an APUF circuit provided by an embodiment of the present invention;
[0044] Figure 4 It is a schematic diagram of a data segmented transmission scheme provided by an embodiment of the present invention;
[0045] Figure 5 It is a schematic diagram of establishing a TCP connection through three-way handshake provided by an embodiment of the present invention;
[0046] Figure 6 It is a structural diagram of a data transmission device provided by an embodiment of the present invention;
[0047] Figure 7 It is a structural diagram of another data transmission device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work belong to the protection scope of the present invention.
[0049] The core of the present invention is to provide a data transmission method, device and medium.
[0050] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0051] In the related art, data is usually encrypted through encryption algorithms to ensure the security during data transmission. Commonly used encryption algorithms include the Advanced Encryption Standard (AES), RSA (a non-symmetric encryption algorithm), Elliptic Curve Cryptography (ECC), and Secure Hash Algorithm (SHA), etc., which belong to one or a combination of symmetric encryption, non-symmetric encryption, hash algorithms, and hybrid encryption. In the current general scenarios, the requirements for data transmission security can already be met by selecting encryption methods with high security coefficients. However, in some scenarios that pay more attention to data security, traditional data encryption algorithms may no longer be able to meet the needs.
[0052] In view of this, the present invention provides a data transmission method, which is applied to at least two network cards including APUF circuits. Among them, the structure of each network card can be as Figure 1 shown, including a control chip and an APUF chip for carrying an Arbiter Physical Unclonable Function (APUF) circuit. Specifically, the control chip is the original core chip in the network card, responsible for implementing the functions originally possessed by the network card, such as all protocol processing, data encapsulation and decapsulation, address filtering and other functions. The APUF chip carries an APUF circuit, which is used to generate a unique and unpredictable response based on the excitation for the control chip to use for data encryption and decryption.
[0053] Furthermore, the data transmission method provided by the present invention is as Figure 2 shown, including:
[0054] S11: Whenever the first network card needs to send a message to the second network card, generate a random excitation and record it as the key excitation.
[0055] S12: Generate a corresponding random response by the APUF circuit based on the key excitation, and encapsulate the random response as the first key in the message to be sent.
[0056] S13: Encrypt the message to be sent with the second key carried in the message sent from the second network card to the first network card most recently, and send the encrypted message to the second network card.
[0057] Wherein, the second key is: the corresponding random response generated by the APUF circuit by the second network card based on the random excitation.
[0058] S21: When receiving the message returned by the second network card, generate a corresponding random response by the APUF circuit based on the key excitation to obtain the first key.
[0059] S22: Decrypt the message returned by the second network card with the first key to obtain the decrypted data and a new second key.
[0060] First of all, it should be noted that the method provided above by the present invention involves the complete process of data transmission, that is, including the sending and receiving of data. Among them, the sending of data corresponds to the above steps S11 to S13, and the receiving of data corresponds to the above steps S21 and S22. In addition, data transmission is a process involving at least two parties, and this method is not limited to being only used for communication between two network cards. However, the communication between three or more network cards can be decomposed into multiple groups of pairwise communications, and both parties in each pairwise communication correspond to the above first network card and second network card. It should also be noted that the first network card and the second network card are not specifically referring to a certain network card in the pairwise communication. In fact, the first network card and the second network card are only a kind of reference. As the data transmission process progresses, the same network card may have two different identities of the first network card and the second network card at different times.
[0061] Exemplarily, assume that there are two network cards A and B, and three data transmissions are respectively performed between them. Among them, the first data transmission is that network card A sends data to network card B, the second data transmission is that network card B sends data to network card A, and the third data transmission is still that network card A sends data to network card B.
[0062] Then for the first data transmission and the second data transmission, the first network card in the above method corresponds to network card A, and the second network card corresponds to network card B. But for the second data transmission and the third data transmission, the first network card in the above method corresponds to network card B, and the second network card corresponds to network card A.
[0063] After that, this embodiment will illustrate the core part in the above method, that is, the APUF circuit for generating keys. As Figure 3As shown in the figure, the APUF circuit mainly consists of three parts: two completely symmetrical circuits, an arbitrator and n switches Ci, where i is an arbitrary integer and i∈[0,m], m=n-1. Among them, the n switches Ci are the input of the APUF circuit, and their main function is to control whether the two completely symmetrical circuits are directly connected or cross-connected at Ci. The two completely symmetrical circuits ensure that the transmission time of the signals on these two symmetrical circuits is only affected by slight differences at the physical level, and the switches Ci will not destroy the symmetry of such circuits. The arbitrator is used to determine the order of arrival of the signals on the two circuits, and output the response according to the order of arrival of the signals on the circuits. In this way, the output response depends only on the physical differences between different circuits caused by different inputs (for example: the extremely small difference in the width of the two circuits caused by manufacturing), which makes the final output unpredictable and unique.
[0064] The stimulus in the above method is the input of the APUF circuit, that is, the control signal input to the n switches Ci. In other words, due to the unique physical characteristics of the APUF circuit, even if the same stimulus is used, multiple APUF circuits produced in the same batch and according to the same design and specifications cannot get the same response.
[0065] After understanding the above principle, this embodiment describes the specific steps in this method:
[0066] Step S11 is a step for generating a key carried during a data transmission process. In this method, the key carried each time data is sent is randomly generated to ensure the uniqueness of each key. Among them, the stimulus can be randomly generated by software methods such as random number generation, or by hardware methods such as a true random number generator, and this embodiment does not limit this. After obtaining the random stimulus, a unique and unpredictable output response can be obtained through the APUF circuit as the first key. The first key is also the key used to encrypt data when the second network card sends a message next time.
[0067] It should be noted that after the first network card obtains the first key based on step S11 and encapsulates the first key in the message, the first network card does not retain the first key, but records the random excitation used to generate the first key, that is, retains the key excitation. From the above description of the physical characteristics of the APUF circuit, it can be seen that as long as the APUF circuit of the first network card remains unchanged, the first key can be reproduced through this key excitation. However, if only the key excitation is obtained without using the APUF circuit in the first network card, it is impossible to obtain a completely identical output response to reproduce the first key.
[0068] That is, in step S11 of the present method, the first key itself is not stored, but the key incentive is stored, so that an attacker cannot obtain the first key stored locally by attacking the first network card. Even if the attacker obtains the first key, due to the physical characteristics of the APUF circuit, the first key cannot be reproduced, so the data encrypted with the first key still cannot be cracked.
[0069] After that, for step S12, it is the step of obtaining the first key. The first key is the output response obtained through the APUF circuit with the encrypted incentive as the input. The first key is encapsulated in the message to be sent, so that the second network card receiving the message can know the key required for encrypting the data in the encrypted message when sending the next message.
[0070] It should be noted that this embodiment does not limit the specific position where the first key is encapsulated in the message. As long as it is pre-agreed with the second network card so that the second network card can obtain the first key from the corresponding position after receiving the message. The first key can be encapsulated in any non-fixed field in the message (such as a customizable field or an extensible field, etc.)
[0071] In addition, the first key encapsulated in the message itself can be encrypted or not. Encrypting it can further improve security, while not encrypting it is beneficial for the second network card to quickly obtain the first key and can improve data transmission efficiency. However, from another perspective, the above scheme of pre-agreeing the position of the first key in the message between the first network card and the second network card can also play a certain "encryption" role.
[0072] For step S13, it is the step of encrypting the data in the message to be sent this time. It should be noted that the encryption of the message here can be only encrypting the data in the message, or encrypting both the data in the message and the additionally carried first key. This embodiment does not limit this.
[0073] In addition, for the second key in step S13. The second key is the second key carried in the message sent by the second network card to the first network card the last time. From the above specific description of the first network card and the second network card, the second network card in the current data transmission process may also be the first network card at other times; so it will also send data through steps S11 to S13; then there will also be a first key (the second key in the current data transmission) in the message it sends.
[0074] However, it should be noted that the situation here does not include the case where the first network card and the second network card perform data transmission for the first time. That is, at this time, for the first network card, since it has not received the message sent by the second network card, it cannot obtain the second key. For this situation, a possible implementation solution is not to encrypt the message sent during the first data transmission.
[0075] Exemplarily, still taking the three - time data transmission example of the above - mentioned two network cards A and B as an example:
[0076] Suppose that during the first data transmission, network card A generates a key X (which is the first key at this time) based on the random excitation x and encapsulates it in message 1; since this is the first data transmission, network card A cannot obtain the second key, so network card A can directly send message 1 to network card B without encrypting it.
[0077] Starting from the second data transmission, network card B can generate a key Y based on the random excitation y and encapsulate it in message 2; since for network card B, there is the previous message 1 sent by network card A, and the key x (which is the second key at this time) is carried in message 1; so network card B can encrypt message 2 with the key x to achieve encrypted data transmission.
[0078] For the third data transmission, network card A generates a key Z based on the random excitation z and encapsulates it in message 3; at this time, for network card A, there is also the previous message 2 sent by network card B, and the key y is carried in message 2; so network card A can encrypt message 3 with the key y to achieve encrypted data transmission.
[0079] In summary, the steps S11 - S13 provided by this method protect a sending scheme during the data transmission process: for each network card, the message sent carries the unique key generated by itself for this data transmission; this key is used for data encryption when other network cards send messages to this network card next time; similarly, the key used for the current message data is also the key carried in the message sent by other network cards to this network card last time.
[0080] Thus, for an attacker, only by intercepting two consecutive messages (such as message 1 and 2, or message 2 and 3 in the above example) can the encrypted data in the latter message be decrypted with the key carried in the previous message. However, in network communication, the routing paths of each Internet Protocol (IP) packet are different. Therefore, it is very difficult for an attacker to intercept consecutive messages between two network cards, greatly increasing the difficulty of cracking the data transmission.
[0081] In addition, for steps S21 and S22 provided by the present method above, they are data receiving methods provided by one network card. For step S21, as can be seen from the above, since the first key was carried in the previous message sent by the first network card, and the first key is the key used for the second network card to encrypt data when sending the next message. Therefore, the message received in step S21 is encrypted with the first key generated in step S12. Also, from step S11 above, it can be known that in the present method, the first key itself is not stored, but the corresponding key incentive is stored. Therefore, step S21 reproduces the first key based on the key incentive through the APUF circuit, so that step S22 can decrypt the message sent by the second network card with the reproduced first key to obtain the original data and complete this data transmission.
[0082] Exemplarily, still taking the three data transmissions between the above network cards A and B as an example. When network card A receives message 2 sent by network card B, it can reproduce key X based on the recorded incentive x, and then parse message 2 through key X to obtain the original data and key Y. After that, network card A will encrypt message 3 with key Y. And when network card B receives message 3, it will reproduce key Y through the recorded incentive y and then decrypt message 3.
[0083] It should also be noted that on the basis of determining the first key as the encryption key, the present embodiment does not limit which encryption method is used to encrypt the data in step S13. From the above descriptions of steps S11 - S13 and steps S21 and S22, it can be seen that in the process of sending and receiving data once, the key used for encryption when one of the two network cards sends data is the same as the key used for decryption when the other network card receives data, that is, it corresponds to the symmetric encryption method. Therefore, by modifying the part related to obtaining the key in the existing symmetric encryption algorithm, the combination of the present method and the existing symmetric encryption algorithm can be quickly and conveniently realized, and the key is determined and data is transmitted based on the present method, while the existing symmetric encryption algorithm is used to encrypt data based on the key to ensure the security during the data transmission process. However, it should be noted that the above example does not mean that the present method can only be combined with the existing symmetric encryption algorithm. When extracting the parts related to encrypting data based on the key in the asymmetric encryption, hash algorithm, and hybrid encryption algorithm, they can also be combined and applied in step S13 of the present method to encrypt the data.
[0084] In addition, regarding how the data is transmitted, as Figure 4 shown, the present embodiment also provides a possible implementation scheme:
[0085] During the data transmission process, the original data is sent in segments, and each data segment contains a sequence number and an acknowledgment number.
[0086] The first network card waits for the acknowledgment character packet (ACK) from the second network card for confirmation, and the unacknowledged data segments will be retransmitted.
[0087] This method ensures the efficient and accurate transmission of data. For the transmission of large amounts of data, the efficiency of each data transmission is ensured by segmented transmission, and the risk of data loss or transmission failure caused by too long data transmission time is avoided. In addition, for the transmission of data segments, the receiving party needs to reply with an ACK packet for confirmation. If the sending party does not receive the ACK packet, it means that the receiving party has not received the corresponding data segment, and at this time, retransmission is required to ensure that the receiving party can receive the complete data.
[0088] In summary, for a data transmission method provided by the present invention, a unique and unpredictable key is generated by an APUF circuit with unique physical characteristics, and encrypting data with this key has better security. In addition, the keys used in each data transmission process in this method are different, and one key is only used for one data transmission, and the life cycle of the key is extremely short. Moreover, the keys required for the next time are carried in the message sent this time, so that the attacker can only crack the encrypted content in the latter message by intercepting two consecutive messages. And because each IP packet has a different routing path in network communication, it is difficult for the attacker to intercept consecutive messages, that is, the security of this method is guaranteed. Furthermore, the key used to encrypt data in this method is not retained in the network card, so that the attacker cannot obtain the key by attacking the network card itself to crack the transmitted data. And even if the attacker obtains the key excitation, due to the unique physical characteristics of the APUF circuit, the corresponding key cannot be reproduced, thus further ensuring the security of data transmission. It can be seen that this method effectively guarantees the security in data transmission in the above three aspects, and is a data transmission scheme with higher security and reliability.
[0089] On the other hand, as can be seen from the above, this method can effectively guarantee the security in the data transmission process. However, the security of data transmission is reflected in many aspects. In addition to ensuring that the transmitted data cannot be cracked, ensuring that a real communication connection can be established between the first network card and the second network card, rather than establishing a communication connection with the attacker, is also an aspect of the security in the data transmission process. In view of this, this embodiment further provides a possible implementation scheme:
[0090] The message encrypted by the first key or the second key further includes: handshake messages sent between the first network card and the second network card when establishing and / or disconnecting the communication connection with each other.
[0091] That is to say, in this embodiment, in addition to the formal data transmission process, the handshake communication required for establishing and / or disconnecting the communication connection between the first network card and the second network card is also included in the protection scope. The handshake message data is also encrypted in the above-mentioned manner to ensure the security when establishing and / or disconnecting the communication connection.
[0092] To better illustrate the solution provided in this embodiment, this embodiment takes a common current communication method - Transmission Control Protocol (TCP) as an example for illustration:
[0093] The process of establishing a TCP connection is as Figure 5 shown. Establishing a TCP connection is accompanied by three "handshakes". Specifically, the three-way handshake process for establishing a TCP connection is as Figure 4 shown. The client (i.e., the above-mentioned network card, such as the first network card) sends a Synchronize Sequence Numbers (SYN) packet to the server (also the above-mentioned network card, but another network card different from the corresponding client's network card, such as the second network card), indicating a request to establish a connection. After receiving it, the server sends a SYN+ACK packet to confirm. After the client receives the confirmation, it replies with an ACK packet, and the connection is established.
[0094] Similarly, the interruption of a TCP connection is accompanied by four handshakes. Specifically, when releasing the connection (i.e., interrupting), in order to ensure that both parties can release the connection resources after sending data, after the client confirms that the data has been sent, it will send a FIN (Finish) packet, indicating that the data has been sent. The server confirms the FIN packet, replies with an ACK packet, and continues to send the unfinished data; and after the server finishes sending the data, it will send a FIN packet, indicating that the data has been sent; at this time, the client replies with an ACK packet, and the connection is closed.
[0095] It should be noted that the above illustration in this embodiment taking the TCP connection as an example is only because TCP is a currently mainstream communication transmission protocol and is representative, and does not mean that this method can only be applied to data transmission implemented based on the TCP protocol.
[0096] It can be seen that in this embodiment, the encryption protection during the data transmission process is extended from encrypting the "data transmission" itself to also encrypting the handshake communication during the establishment of the communication connection required for data transmission. Thus, the data transmission scope protected by this method is further expanded, that is, the security and reliability during the data transmission process are further improved.
[0097] However, it should be specifically noted that, as can be seen from the above embodiments, there may be security risks in the first data transmission of the data transmission method provided by the present invention. That is, in the first data transmission, since there is no second key carried in the previous message sent by the second network card, the data in the first data transmission cannot be encrypted by the second key. At this time, in the above embodiments, an alternative encryption scheme is given: that is, the data is encrypted by the first key randomly generated this time, and the first key is also encapsulated in the message and sent to the second network card together, so that the second network card can decrypt the message to obtain the original data.
[0098] Of course, due to the uncertainty of the position of the first key in the message, the first network card and the second network card need to pre-agree on a unique position. Therefore, it is not easy for an attacker to intercept the message in the first data transmission and extract the first key to decrypt the data. However, this scheme is not as secure as the above method after all, which makes the first data transmission in this method become the weak link in the whole data transmission process.
[0099] However, based on the solution provided in this embodiment, the data encryption is extended from the data transmission itself to the handshake communication when the communication connection is established. That is, at this time, for the formal data transmission, there is no longer a "first transmission" without the second key. For example, in the message 1 in the above example, although it is the first formal data transmission. However, since network card A and network card B perform three-way handshakes when establishing a TCP connection, these three-way handshakes will also be encrypted using this method. Suppose the messages transmitted during these three-way handshakes are 0, 0', and 0''. Then it is not difficult to know that when sending message 1, network card A can encrypt message 1 based on the second key carried in message 0'' transmitted in the last handshake, thus overcoming the problem that the first transmission in the formal data transmission process of this method has a weak link.
[0100] Although the solution to the above problem is essentially to move the weak link from the first formal data transmission to the communication during the first handshake. However, since only the data required for the two parties to establish a connection, such as the SYN packet, will be carried during the handshake and does not involve actual data. So even if an attacker intercepts this message, the information that can be obtained is limited, which can also improve the security in the data transmission process to a certain extent.
[0101] On the other hand, as can be seen from the above embodiments, this method is not limited to the specific position where the first key is encapsulated in the message, and it can be encapsulated in the non-fixed fields of the message. And since the formats of the messages sent are different when the network cards use different communication protocols to transmit data. Therefore, taking the TCP protocol as an example, this embodiment gives a specific implementation scheme for encapsulating the first key in the message.
[0102] First of all, the message format based on the TCP protocol is as shown in Table 1 below:
[0103] Table 1 TCP Packet Content
[0104]
[0105] As can be seen from the superscript 1, the non-fixed fields in the TCP packet where the first key can be written include the option field and the data part. Among them, the data part is also the part that carries the data to be transmitted in the packet. In other words, if the first key is encapsulated in the data part, it is equivalent to the first key and the data to be transmitted being mixed and encapsulated in the TCP packet for transmission. Since it involves the data to be transmitted, the first network card and the second network card need to pre-agree on the specific position of the first key in the data part to avoid obtaining the wrong first key.
[0106] In another possible implementation, the first key can be encapsulated in the option field of the TCP packet. At this time, the first network card and the second network card do not need to further agree on the specific position of the first key, and can directly extract the data from the option field of the TCP packet to obtain the first key, which is easier to implement.
[0107] That is, this embodiment provides a possible implementation:
[0108] The first network card and the second network card are communicatively connected through a communication transmission protocol.
[0109] At this time, the above step S12 is specifically: encapsulate the first key in the option field of the packet to be sent.
[0110] As can be seen from the above, in this embodiment, by encapsulating the first key in the option field of the TCP packet, the encapsulation and acquisition of the first key are both easier to implement, improving the data transmission efficiency and reducing the implementation difficulty of this method.
[0111] Further, in the above embodiment, it is not restricted whether the first key encapsulated in the packet is encrypted. However, a possible implementation is given, that is, encrypt the first key to obtain higher data transmission security and reliability. However, for how to encrypt the first key, this embodiment also provides a corresponding implementation. The above step S13 specifically further includes:
[0112] Use the second key to encrypt the data and the first key carried in the packet to be sent.
[0113] That is, in this embodiment, in addition to encrypting the data to be transmitted carried in the message, the second key is also used to encrypt the first key. As can be seen from the above, the second key is a key generated by the second network card itself when sending data and encapsulated in the message. Therefore, the corresponding key incentive is stored in the second network card. Using the second key to encrypt the first key, the second network card can decrypt to obtain the original first key after receiving the message. This solution does not require an additional agreement or transmission of a key for encrypting the first key. Moreover, it can be compatible with the advantages of the above method in the data transmission process, that is, the security guarantee brought by the uniqueness and unpredictability of the key, as well as the replacement of the key for each transmission and the short life cycle of the key due to the key not being retained in the network card.
[0114] More importantly, in this embodiment, the second key is used to encrypt the first key, so that the keys used in each data transmission process are organically combined. That is, if an attacker wants to crack the data carried in the i-th message, he needs to know the first key (which is the second key for the i-th message) carried in the (i - 1)-th message. However, the first key carried in the (i - 1)-th message is encrypted by the first key carried in the (i - 2)-th message. Therefore, if an attacker wants to crack the data carried in any message, he must obtain all the messages before this message. Especially when the message encrypted by this method in this embodiment is extended to the handshake message for establishing communication between network cards, the attacker must obtain all the messages from the first handshake to the current message in order to crack the data carried in them, which has a high security protection ability.
[0115] In addition, it should be noted that this embodiment can be combined with the previous embodiment for application. That is, the first key is encapsulated in the option field of the TCP message and encrypted by the second key. It can also be implemented independently, that is, the first key is encapsulated in the data part of the TCP message and can also be encrypted by the second key.
[0116] Furthermore, as can be seen from the solution provided by the above embodiment, by extending the message encrypted by this method from the formal data transmission message to the handshake message sent during establishment and / or connection, the weak link can be transferred from the first formal data transmission to the first handshake communication, thereby further improving the security of data transmission.
[0117] However, this problem itself has not been solved. Since there is no previous message sent by the second network card during the first handshake, the first network card does not have a key agreed with the second network card. At this time, for how to encrypt the data in the message, this embodiment provides a corresponding implementation scheme. For the message of the first handshake sent by the first network card and the second network card when establishing a communication connection, the above method further includes:
[0118] S14: Encrypt the data part of the message using the first key, and encapsulate the unencrypted first key in the option field of the message.
[0119] That is, in this embodiment, since there is no second key, the first network card encrypts the data using the first key generated during this data transmission process to ensure data security. At the same time, since the second network card does not know the first key in advance, in order to ensure that the encrypted data can be decrypted by the second network card, the unencrypted first key is also carried in the message. Further, to prevent an attacker from directly decrypting the data through the unencrypted first key carried in the intercepted message, in this embodiment, the first key is encapsulated in the option field of the message. It is equivalent to protecting the first key by pre-agreeing on the position of the first key with the second network card. If the attacker does not know the encapsulation position of the first key in advance, or even does not know the encryption mode used in this method, then intercepting this message does not know that the message data is encrypted using the first key, and even less knows that the first key is encapsulated in the option field of the message, which ensures the security of data communication during the first handshake to a certain extent.
[0120] In addition, for the security of data communication during the first handshake mentioned above, this embodiment also provides a further implementation. Before the above step S14, this method further includes:
[0121] S151: Determine whether there is a third key retained in the local storage; if it exists, go to step S152.
[0122] The third key is: the second key carried in the last handshake message when the second network card disconnects the communication connection with the first network card. It is not difficult to understand that if it is determined in step S151 that there is no third key retained, the message encryption during the first handshake can be achieved through step S14.
[0123] S152: Encapsulate the first key in the option field of the message, and encrypt the option field and the data part of the message using the third key.
[0124] In this embodiment, the first handshake communication between the first network card and the second network card in this communication connection does not represent the first real communication between the first network card and the second network card after they are put into use. For example, there may have been data transmission between the first network card and the second network card before, but due to a connection interruption, a communication connection still needs to be re-established at this time, that is, there is the above-mentioned first handshake communication. At this time, for this method, it is to retain the second key carried in the packet at the last communication during the previous communication process as the third key for use as the encryption key during the first handshake in the process of establishing this communication. This method can fundamentally solve the weak link existing in the first handshake communication during the non-first establishment of a communication connection. That is, as long as the first network card and the second network card are not the first real communication, the packet sent this time can be encrypted with the key carried in the previous communication packet. Thus, the weak link is reduced from the first handshake during each communication connection establishment to the first handshake during the first communication connection establishment, greatly reducing the possibility of being cracked.
[0125] Specifically, the solution provided in this embodiment has good protection against the attack method where an attacker repeatedly attempts to send a communication connection establishment request to the network card to crack the encrypted data through the weak link during the first handshake.
[0126] Furthermore, although the above embodiment reduces the scope of the weak link, there is also a new problem: for the third key, since it needs to be retained in the network card, it will destroy the feature that all the keys used for encrypting data in this method are not retained in the network card, which will affect the protection ability to a certain extent. In response to this, this embodiment provides a targeted solution. The above method further includes:
[0127] S153: When the retention duration of the third key exceeds the preset retention threshold, delete the third key from the local storage.
[0128] That is, in this embodiment, a retention threshold is set for the third key to specify the maximum retention duration allowed for the third key; it is ensured that although the third key is allowed to be retained, the life cycle of the third key is very short; it increases the difficulty for an attacker to obtain the third key by attacking the network card and then crack the encrypted data. And when the retention duration of the third key exceeds the retention threshold and is deleted, the packet encryption during the first handshake can still be achieved through the above step S14.
[0129] Specifically, the solution provided in this embodiment has good protection capabilities against the attack method where an attacker attempts to send communication connection establishment requests to the network card multiple times within a short period to crack encrypted data through the weak link during the first handshake. When the attack time is extended, although the probability of successful attack will increase, on the one hand, this does not conform to the behavior pattern of general attack behaviors. On the other hand, the extended attack time also provides sufficient reaction time for security protection personnel to detect the attack behavior and take targeted protection measures, which can also ensure the security and reliability during the data transmission process.
[0130] In addition to the embodiments of a data transmission method provided above, the present invention also provides an embodiment corresponding to a computer program product. A computer program product includes computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the data transmission method described in any of the above embodiments can be implemented.
[0131] Since the embodiments in the computer program product part correspond to the embodiments in the method part, for the embodiments in the computer program product part, please refer to the description of the embodiments in the method part, and will not be elaborated here for the time being.
[0132] In the above embodiments, a data transmission method is described in detail. The present invention also provides an embodiment corresponding to a data transmission device. It should be noted that the present invention describes the embodiments of the device part from two perspectives, one is from the perspective of functional modules, and the other is from the perspective of hardware.
[0133] From the perspective of functional modules, as Figure 6 shown, this embodiment provides a data transmission device, which is applied to at least two network cards including APUF circuits, and includes:
[0134] A random key module 11, configured to generate a random excitation and record it as a key excitation whenever the first network card needs to send a message to the second network card.
[0135] A key encapsulation module 12, configured to generate a corresponding random response by the APUF circuit based on the key excitation, and encapsulate the random response as a first key in the message to be sent.
[0136] A data encryption module 13, configured to encrypt the message to be sent through the second key carried in the message recently sent from the second network card to the first network card, and send the encrypted message to the second network card; wherein, the second key is: the corresponding random response generated by the APUF circuit of the second network card based on the random excitation.
[0137] The key reproduction module 14 is configured to, when receiving a message returned by the second network card, generate a corresponding random response by the APUF circuit based on a key excitation to obtain a first key.
[0138] The data decryption module 15 is configured to decrypt the message returned by the second network card with the first key to obtain decrypted data and a new second key.
[0139] Since the embodiments in the apparatus part correspond to those in the method part, for the embodiments in the apparatus part, please refer to the descriptions of the embodiments in the method part, which will not be elaborated here.
[0140] Figure 7 The structural diagram of a data transmission apparatus provided in another embodiment of the present invention is as Figure 7 shown. A data transmission apparatus includes: a memory 20 configured to store a computer program;
[0141] a processor 21 configured to implement the steps of a data transmission method as described in the above embodiment when executing the computer program.
[0142] The data transmission apparatus provided in this embodiment may include, but is not limited to, a network card, a mobile terminal, a personal computer, a workstation, etc.
[0143] Wherein, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), or a programmable logic array. The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.
[0144] The memory 20 may include one or more computer-readable storage media, which may be non-transitory. The memory 20 may also include high-speed random access memory, as well as non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 20 is at least used to store the following computer program 201. After the computer program is loaded and executed by the processor 21, it can implement the relevant steps of a data transmission method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 20 may also include an operating system 202 and data 203, etc., and the storage method may be transient storage or permanent storage. Among them, the operating system 202 may include Windows, Unix, Linux, etc. The data 203 may include, but is not limited to, a data transmission method, etc.
[0145] In some embodiments, a data transmission device may further include a display screen 22, an input / output interface 23, a communication interface 24, a power supply 25, and a communication bus 26.
[0146] Those skilled in the art can understand that Figure 7 the structure shown in does not constitute a limitation on a data transmission device, and it may include more or fewer components than shown in the figure.
[0147] A data transmission device provided by an embodiment of the present invention includes a memory and a processor. When the processor executes the program stored in the memory, it can implement the following method: A data transmission method.
[0148] Finally, the present invention also provides an embodiment corresponding to a non-volatile storage medium. A computer program is stored on the non-volatile storage medium, and when the computer program is executed by the processor, it implements the steps recorded in the above method embodiments.
[0149] It can be understood that if the method in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in various embodiments of the present invention. And the foregoing storage media include: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, etc., which can store program codes.
[0150] The above has introduced in detail a data transmission method, apparatus and medium provided by the present invention. The various embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part. It should be noted that for those of ordinary skill in the art in the technical field of the present invention, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
[0151] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the said element.
Claims
1. A data transmission method, characterized in that, Applied to at least two network cards including APUF circuits, the method includes: Whenever the first network card needs to send a message to the second network card, generate a random excitation and record it as a key excitation; Based on the key excitation, generate a corresponding random response by the APUF circuit, and encapsulate the random response as a first key in the message to be sent; Encrypt the message to be sent through the second key carried in the message sent by the second network card to the first network card most recently, and send the encrypted message to the second network card; wherein, the second key is: the corresponding random response generated by the APUF circuit based on the random excitation by the second network card; When receiving the message returned by the second network card, generate a corresponding response by the APUF circuit based on the key excitation to obtain the first key; Decrypt the message returned by the second network card through the first key to obtain the decrypted data and the new second key.
2. The data transmission method according to claim 1, wherein The message encrypted through the first key or the second key further includes: the handshake messages sent to each other when the first network card and the second network card establish and / or disconnect the communication connection.
3. The data transmission method according to claim 2, wherein The first network card and the second network card achieve a communication connection through a communication transmission protocol; Encapsulating the random response as the first key in the message to be sent includes: Encapsulating the first key in the option field of the message to be sent.
4. The data transmission method according to claim 3, wherein Encrypting the message to be sent through the second key carried in the message sent by the second network card to the first network card most recently includes: Encrypting the data carried in the message to be sent and the first key through the second key.
5. The data transmission method according to claim 4, wherein For the message of the first handshake sent by the first network card and the second network card when establishing a communication connection, the method further includes: Encrypt the data part of the message through the first key, and encapsulate the unencrypted first key in the option field of the message.
6. The data transmission method according to claim 5, wherein Before encrypting the data part of the message through the first key and encapsulating the unencrypted first key in the option field of the message, it further includes: Judge whether there is a third key retained in the local storage; wherein, the third key is: the second key carried in the last handshake message when the second network card disconnects the communication connection with the first network card; If it exists, encapsulate the first key in the option field of the message, and encrypt the option field and the data part of the message through the third key.
7. The data transmission method according to claim 6, wherein It further includes: When the retention duration of the third key exceeds a preset retention threshold, delete the third key from the local storage.
8. A data transmission device, characterized in that, Applied to at least two network cards including APUF circuits, it includes: A random key module, used to generate a random excitation and record it as a key excitation whenever the first network card needs to send a message to the second network card; A key encapsulation module, used to generate a corresponding random response by the APUF circuit based on the key excitation, and encapsulate the random response as a first key in the message to be sent; A data encryption module, configured to encrypt the data of the packet to be sent by using a second key carried in the packet sent by the second network card to the first network card most recently, and send the encrypted packet to the second network card; wherein, the second key is: a corresponding random response generated by the APUF circuit based on a random excitation by the second network card; A key reproduction module, configured to, when receiving a packet returned by the second network card, generate a corresponding random response by the APUF circuit based on the key excitation to obtain the first key; A data decryption module, configured to decrypt the packet returned by the second network card by using the first key to obtain decrypted data and a new second key.
9. A data transmission device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to implement the steps of the data transmission method according to any one of claims 1 to 7 when executing the computer program.
10. A non-volatile storage medium, characterized in that, A computer program is stored on the non-volatile storage medium, and when the computer program is executed by a processor, the steps of the data transmission method according to any one of claims 1 to 7 are implemented.